Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23836 | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments containing cross-site scripting as detailed in CVE-2023-1602, granted they can trick a site administrator into performing an action such as clicking on a link. |
Mon, 19 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 17 Aug 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments containing cross-site scripting as detailed in CVE-2023-1602, granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Short URL <= 1.6.8 - Cross-Site Request Forgery via configuration_page | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:17:56.690Z
Reserved: 2023-03-23T15:49:40.437Z
Link: CVE-2023-1604
Updated: 2024-08-19T13:47:56.155Z
Status : Deferred
Published: 2024-08-17T08:15:05.090
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-1604
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:14Z
EUVD